lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20250402093609.GK214849@horms.kernel.org>
Date: Wed, 2 Apr 2025 10:36:09 +0100
From: Simon Horman <horms@...nel.org>
To: Debin Zhu <mowenroot@....com>
Cc: pabeni@...hat.com, 1985755126@...com, kuba@...nel.org,
	linux-kernel@...r.kernel.org, netdev@...r.kernel.org,
	paul@...l-moore.com
Subject: Re: [PATCH v3] netlabel: Fix NULL pointer exception caused by
 CALIPSO on IPv4 sockets

On Tue, Apr 01, 2025 at 08:40:18PM +0800, Debin Zhu wrote:
> When calling netlbl_conn_setattr(), addr->sa_family is used
> to determine the function behavior. If sk is an IPv4 socket,
> but the connect function is called with an IPv6 address,
> the function calipso_sock_setattr() is triggered.
> Inside this function, the following code is executed:
> 
> sk_fullsock(__sk) ? inet_sk(__sk)->pinet6 : NULL;
> 
> Since sk is an IPv4 socket, pinet6 is NULL, leading to a
> null pointer dereference.
> 
> This patch fixes the issue by checking if inet6_sk(sk)
> returns a NULL pointer before accessing pinet6.
> 
> Fixes: ceba1832b1b2("calipso: Set the calipso socket label to match the secattr.")

There is probably no need to repost for this, but
there is a missing space in the Fixes tag. It should be like this:

Fixes: ceba1832b1b2 ("calipso: Set the calipso socket label to match the secattr.")

> Signed-off-by: Debin Zhu <mowenroot@....com>
> Signed-off-by: Bitao Ouyang <1985755126@...com>
> Acked-by: Paul Moore <paul@...l-moore.com>

...

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ